What is CWE-22?
The product uses external input to construct a pathname intended to remain under a restricted parent directory, but fails to neutralize special pathname elements that can resolve it outside that directory.
The product uses external input to construct a pathname intended to remain under a restricted parent directory, but fails to neutralize special pathname elements that can resolve it outside that directory.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Many file operations are intended to take place within a restricted directory. By using special elements such as ".." and "/" separators, attackers can escape outside of the restricted location to access files or directories that are elsewhere on the system. One of the most common special elements is the "../" sequence, which in most modern operating systems is interpreted as the parent directory of the current location. This is referred to as relative path traversal. Path traversal also covers the use of absolute pathnames such as "/usr/local/bin" to access unexpected files. This is referred to as absolute path traversal.
Path traversal occurs when pathname processing allows an attacker-controlled path to escape its intended directory boundary. Relative traversal commonly uses .. with / separators, while absolute traversal supplies a complete pathname such as /usr/local/bin; the record also identifies the broader issue as including platform-specific path handling. The resulting operation may target files or directories elsewhere on the system instead of only the restricted location.
This is a base, simple weakness introduced during implementation when external input is used in file or directory operations without adequate pathname validation, decoding, canonicalization, or boundary enforcement. It can arise through relative or absolute paths, archive extraction, upload metadata, file-management commands, included files, and similar interfaces. The official record describes path traversal as preferred terminology over directory traversal, while also listing both terms and the alternate phrasing path transversal.
Potential consequences span confidentiality, integrity, and availability. An attacker may read unexpected files, create or overwrite programs, libraries, important data, or security-related files, potentially bypass authentication or enable unauthorized code or command execution. Overwriting, deleting, or corrupting critical files may also crash, restart, disable, or lock out users of the product.
| Impact | Scope | Explanation |
|---|---|---|
| Execute Unauthorized Code or Commands | Integrity, Confidentiality, Availability | The attacker may be able to create or overwrite critical files that are used to execute code, such as programs or libraries. |
| Modify Files or Directories | Integrity | The attacker may be able to overwrite or create critical files, such as programs, libraries, or important data. If the targeted file is used for a security mechanism, then the attacker may be able to bypass that mechanism. For example, appending a new account at the end of a password file may allow an attacker to bypass authentication. |
| Read Files or Directories | Confidentiality | The attacker may be able read the contents of unexpected files and expose sensitive data. If the targeted file is used for a security mechanism, then the attacker may be able to bypass that mechanism. For example, by reading a password file, the attacker could conduct brute force password guessing attacks in order to break into an account on the system. |
| DoS: Crash, Exit, or Restart | Availability | The attacker may be able to overwrite, delete, or corrupt unexpected critical files such as programs, libraries, or important data. This may prevent the product from working at all and in the case of protection mechanisms such as authentication, it has the potential to lock out product users. |
Use layered controls grounded in the official record:
. when feasible, exclude directory separators, and constrain extensions. Do not rely solely on denylists or dangerous-character removal, because alternate separators and other bypasses may remain.realpath in C or PHP, getCanonicalPath in Java, GetFullPath in ASP.NET, or abs_path in Perl, while accounting for .. sequences and symbolic links.chroot, AppArmor, SELinux, or Java java.io.FilePermission can restrict accessible files or commands, but their effectiveness is limited and depends on the specific implementation; they may only reduce scope and require care to avoid jail-related weaknesses.register_globals, and do not create an unsafe emulation of it.The official record identifies several complementary detection approaches:
Automated techniques may need customization to distinguish administrator-only or otherwise privileged behavior from exploitable weaknesses. No single approach is stated to provide complete coverage.
| Method | Approach | Effectiveness |
|---|---|---|
| Automated Static Analysis | Automated techniques can find areas where path traversal weaknesses exist. However, tuning or customization may be required to remove or de-prioritize path-traversal problems that are only exploitable by the product's administrator - or other privileged users - and thus potentially valid behavior or, at worst, a bug instead of a vulnerability. | High |
| Manual Static Analysis | Manual white box techniques may be able to provide sufficient code coverage and reduction of false positives if all file access operations can be assessed within limited time constraints. | High |
| Automated Static Analysis - Binary or Bytecode | According to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Bytecode Weakness Analysis - including disassembler + source code weakness analysis ``` Cost effective for partial coverage: ``` Binary Weakness Analysis - including disassembler + source code weakness analysis | High |
| Manual Static Analysis - Binary or Bytecode | According to SOAR [REF-1479], the following detection techniques may be useful: ``` Cost effective for partial coverage: ``` Binary / Bytecode disassembler - then use manual analysis for vulnerabilities & anomalies | SOAR Partial |
| Dynamic Analysis with Automated Results Interpretation | According to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Web Application Scanner Web Services Scanner Database Scanners | High |
| Dynamic Analysis with Manual Results Interpretation | According to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Fuzz Tester Framework-based Fuzzer | High |
| Manual Static Analysis - Source Code | According to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Manual Source Code Review (not inspections) ``` Cost effective for partial coverage: ``` Focused Manual Spotcheck - Focused manual analysis of source | High |
| Automated Static Analysis - Source Code | According to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Source code Weakness Analyzer Context-configured Source Code Weakness Analyzer | High |
| Architecture or Design Review | According to SOAR [REF-1479], the following detection techniques may be useful: ``` Highly cost effective: ``` Formal Methods / Correct-By-Construction ``` Cost effective for partial coverage: ``` Inspection (IEEE 1028 standard) (can apply to requirements, design, source code, etc.) | High |
The official record lists the following representative examples, not an exhaustive set:
CVE-2024-37032: An LLM management tool enabled relative traversal through an unvalidated digest from an untrusted model registry.CVE-2024-4315: An LLM text-generation API omitted the Windows \ separator from a denylist, allowing arbitrary file deletion on Windows.CVE-2024-0520: An AI dataset-management product allowed relative and absolute traversal through Content-Disposition to overwrite files.CVE-2022-45918: A learning-management debugger used an insufficiently validated path to locate session logs through ../ sequences.CVE-2019-20916: A Python package manager allowed arbitrary file reads through traversal in a Content-Disposition filename.CVE-2022-31503: An unsafe Python os.path.join use allowed an absolute input path to replace the intended pathname.CVE-2022-24877: A Go Kubernetes operator allowed access to files in its controller pod through ../ in YAML.CVE-2021-21972: An unauthenticated archive upload combined with .. traversal to access unexpected files, and was exploited in the wild according to the record.CVE-2020-4053 and CVE-2019-10743: Go package or archive handling allowed files from malicious plugin or ZIP archives to be copied or extracted outside the intended directory, known as Zip Slip.CVE-2020-3452: Improper input validation in a security product led to directory traversal and was exploited in the wild according to the record.CVE-2010-0467: A newsletter module allowed arbitrary file reads through ../.CVE-2006-7079: A PHP compatibility layer using extract for register_globals compatibility enabled traversal.CVE-2009-4194, CVE-2009-4053, and CVE-2009-0244: FTP-related services allowed arbitrary deletion, directory creation, directory listing, or file reading through .. sequences.CVE-2009-4013 and CVE-2010-0012: Package or torrent processing allowed arbitrary file overwriting through .. or ../.CVE-2010-0013: A chat program allowed file overwriting through a custom smiley request.CVE-2009-4449: A bulletin board allowed attackers to determine whether files existed.CVE-2009-4581: A PHP program allowed arbitrary code execution when .. appeared in filenames passed to include.CVE-2008-5748: External control of language and theme values enabled traversal.CVE-2009-1936: A library-file redirect check still allowed execution when the file was directly requested, enabling remote file inclusion and traversal.Below are representative vulnerabilities related to this CWE, prioritized by severity.
CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScanen